- Keep the medical device file complete and navigable per device family
- Maintain design controls with a traceability matrix from input to validation
- Track complaints through evaluation, investigation and the reportability decision
- Hold sterilisation and process validation records with revalidation triggers defined
- Carry CAPA with regulatory conformity impact assessed on every action
ISO 13485:2016
The medical device quality standard. Unlike ISO 9001 it exists for regulatory purposes, so design controls, the device file and reporting to authorities carry the weight.
- 4Quality management system7
- 5Management responsibility2
- 6Resource management2
- 7Product realization14
- 8Measurement, analysis and improvement9
ISO 13485, in practice.
Medical devices. Quality management systems. Requirements for regulatory purposes.
Manufacturers, and the importers, distributors and service providers in the device supply chain, usually because a regulator or a notified body requires it.
The clause numbers and titles above are the standard's own public structure. The standard itself is copyright of its issuing body and you buy it from them. What we add is the interpretation underneath, and that lives in your workspace.
Every month, on a schedule you can check.
This is the running work for this standard specifically. The general shape is the same across all of them.
- Medical device file index per device family
- Design traceability matrix with verification and validation results
- Complaint files with reportability decisions and justification
- Sterilisation batch records traceable to device batches
- Supplier quality agreements with change notification clauses
Each one is filed against the requirement it satisfies as the work happens, so the pack for the next visit already exists.
Standards that share the structure.
ISO 9001:2015
The quality management standard most certified organisations start with, and the one most other management system standards borrow their structure from.
ISO 22301:2019
The continuity standard, built around one question: when the thing you deliver stops, how quickly does it come back, and who decided that was fast enough.
SOC 2 (TSC 2017, rev. 2022)
Not a certification but an attestation. An independent auditor reports on whether your controls were designed properly, and for Type II, whether they operated over a period.
Name a clause in ISO 13485 and we will open it.
The requirement, the control attached to it, the evidence that satisfies it, and the audit checklist it generates. Nothing prepared in advance, because there is nothing to prepare.
